Linux.Siggen.3456
Added to the Dr.Web virus database:
2020-11-28
Virus description added:
2020-11-28
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
Kills the following processes:
Performs operations with the file system:
Creates or modifies files:
Network activity:
Awaits incoming connections on ports:
Establishes connection:
- 8.#.8.8:53
- 19#.##9.147.16:4321
- 37.##.150.53:7685
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
- 19#.##9.147.16:4321
- 37.##.150.53:7685
- 0.0.0.0:0
- 80.##.73.96:23
- 11#.##3.222.101:23
- 58.##6.0.100:23
- 63.#.117.36:23
- 65.##.122.40:23
- 13#.#3.85.74:23
- 12#.##3.196.102:23
- 27.##4.88.61:23
- 12#.##9.66.160:23
- 23#.#3.201.5:23
- 24#.##.178.165:23
- 15#.##1.195.5:23
- 94.###.95.100:23
- 19#.##7.214.219:23
- 16#.##2.41.133:23
- 19#.##.173.14:23
- 14#.##.171.91:23
- 76.##.37.58:23
- 10#.##.87.172:23
- 25#.##.17.150:23
- 15#.#8.38.36:23
- 18.###.31.109:23
- 9.###.28.135:23
- 35.##.9.70:23
- 18#.#.57.100:23
- 75.###.131.119:23
- 12#.##2.153.95:23
- 18#.##.239.31:23
- 17#.##5.64.10:23
- 21#.##6.189.235:23
- 18#.##.249.11:23
- 70.##.192.250:23
- 1.##.213.158:23
- 3.##.56.63:23
- 24#.##6.238.31:23
- 15#.##1.105.60:23
- 19#.##0.221.56:23
- 95.###.235.58:23
- 30.###.90.194:23
- 13#.#2.130.0:23
- 12#.##2.221.79:23
- 11#.##4.44.244:23
- 76.##.214.186:23
- 19.##.137.48:23
- 12#.##.254.140:23
- 18#.##9.194.101:23
- 54.##.89.152:23
- 17#.##.47.208:23
- 21#.##.103.81:23
- 22#.##5.242.134:23
- 17#.##.221.230:23
- 12#.##.15.183:23
- 17#.##4.110.104:23
- 13#.##.39.211:23
- 13#.##6.90.101:23
- 12#.##0.49.22:23
- 22#.##5.229.247:23
- 19.###.61.242:23
- 21#.##.232.108:23
- 23#.##.102.152:23
- 5.#.#6.146:23
- 25#.##8.233.132:23
- 12#.##2.104.140:23
- 20.##8.64.97:23
- 23#.##9.188.158:23
- 19.##2.8.183:23
- 54.###.190.170:23
- 10#.##2.181.248:23
- 21#.##.216.63:23
- 13#.##8.235.147:23
- 22#.##.197.224:23
- 70.##.39.97:23
- 13#.##4.112.224:23
- 82.###.224.155:23
- 20#.##9.130.104:23
- 61.###.135.131:23
- 21#.##3.159.58:23
- 21#.##3.201.60:23
- 16#.##.186.85:23
- 83.###.142.86:23
- 11#.##8.39.253:23
- 11#.##1.116.165:23
- 8.##.143.232:23
- 37.##.252.252:23
Receives data from the following servers:
- 37.##.150.53:7685
- 19#.##9.147.16:4321
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息